Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6959217
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 27, 20262026-05-27T15:14:33+00:00 2026-05-27T15:14:33+00:00

Currently, I have: $(#upvote).click(function(){ var up = parseInt(document.getElementById(‘voteScore’).innerHTML); up++; document.getElementById(‘voteScore’).innerHTML = up; $.ajax(include/mysql_lib.php?op=upvote&v1=<?php echo

  • 0

Currently, I have:

$("#upvote").click(function(){
    var up = parseInt(document.getElementById('voteScore').innerHTML);
    up++;
    document.getElementById('voteScore').innerHTML = up;
    $.ajax("include/mysql_lib.php?op=upvote&v1=<?php echo $id; ?>");
});

There are two problems I have this with. First, I’m using GET to send variables, which makes me nervous. Secondly, the mysql_lib.php script is right there in my web root. I would much prefer having it in my hosting provider’s protected directory instead of public.

Is this possible?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-27T15:14:34+00:00Added an answer on May 27, 2026 at 3:14 pm

    I would much prefer having it in my hosting provider’s protected directory instead of public.

    If you want to make requests to a web resource, it needs to be publicly visible somehow, no way around that.

    You need to make sure that there’s nothing one can do with mysql_lib.php that is destructive, like op=delete or something, and there’s no way to arbitrarily access resources one is not supposed to see (like by changing the id parameter).

    Also, to avoid gaming, you may want to impose some limits on how often a resource can be upvoted from a single client (that’s a complex issue though; there is a lot of good reading on it here on Stack Overflow.)

    First, I’m using GET to send variables, which makes me nervous.

    Whether you use POST or GET doesn’t make a difference security-wise, but using POST would be more fitting, as you are changing state on the server. You can use POST with jQuery’s Ajax.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

jQuery: $(.upvote).click(function() { var id = $(this).attr('id'); var changeImage = ($(this).children('img').attr('src') === siteUrl +
Currently have this: foreach (var series in Chart1.Series) { series.Enabled = false; } I
I currently have an MS Access application that connects to a PostgreSQL database via
I currently have speakers set up both in my office and in my living
I currently have an existing database and I am using the LINQtoSQL generator tool
We currently have a company email server with Exchange, and a bulk email processing
I currently have a fairly robust server-side validation system in place, but I'm looking
I currently have heavily multi-threaded server application, and I'm shopping around for a good
We currently have code like this: Dim xDoc = XDocument.Load(myXMLFilePath) The only way we
I currently have a class and I'm trying to create an easy GUI to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.